CVE-2026-9352General

LOWCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of the component Messaging Gateway Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-24: 1Mentions · 2026-05-27: 1Active Exploitation · 2026-05-27: 105-2405-27
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-241
General1
2026-05-271
Active Exploitation1
Full discourse2 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting NousResearch hermes-agent (CVE-2026-9352) https://vuldb.com/vuln/365315/cti

    Post summary

    The CTI team reports widespread activity targeting CVE-2026-9352, indicating it is being actively exploited in the wild.

    0000086
    2.2K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-9352 A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of th… https://www.cve.org/CVERecord?id=CVE-2026-9352

    Post summary

    A weakness has been identified in the NousResearch hermes‑agent's _make_run_env function, but no information on exploitability, PoC, patch, or active exploitation is provided.

    00000214
    57.5K followersView on X

Explore more